Skip to content
Offensive360

Offensive360

Category: SAST
License: Commercial (free SAST for public open-source repositories)
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated October 5, 2026
11 min read
Key Takeaways
  • 60+ languages for SAST, per the vendor; the knowledge base documents 15 source-language families, from C# and Java to Apex and Oracle Forms/PL/SQL
  • 40+ active exploit checks and 19 passive analyzers in DAST, with a headless-Chromium crawler and a self-hosted out-of-band callback service
  • 1 virtual appliance (OVA or Azure VHD) carries SAST, DAST, MAST and ASM, and core language engines have analyzed fully offline since August 2026
  • 0 per-developer seat fees: Offensive360 sells a custom annual license and publishes no list prices
  • 30-day renewable scan tokens give public repositories on GitHub, GitLab, Bitbucket and Codeberg free SAST, with SARIF upload to GitHub code scanning

Offensive360 is a commercial SAST and DAST platform from O360 B.V., based in Amsterdam. Both scanners, plus mobile and attack surface modules, run from one virtual appliance that works fully offline.

The company says it was founded by offensive security professionals. It builds its scanning engines in-house rather than wrapping third-party tools, and it sells a custom annual license with no per-developer fee.

Offensive360 dashboard showing projects, scans, vulnerability counts, vulnerabilities by scan group and severity distribution

What is Offensive360?

Offensive360 is the application security brand of O360 B.V. The footer of its site lists the company as ISO/IEC 27001 certified.

The product line covers source code, running applications, mobile packages, container artifacts and external assets. AI Pentester and Autonomous Red Teaming run on the DAST engine. An early-access GRC module takes in scan evidence.

ModuleWhat it covers
SASTSource analysis with taint and data-flow tracking; 60+ languages per the vendor, 15 language families in the knowledge base
Dependency, malware, licensePackage advisories, malware and binary tampering, and license compliance, run alongside a SAST scan
DASTWeb apps and REST/GraphQL APIs; 40+ active checks, 19 passive analyzers, authenticated scanning
MASTAndroid APK/AAB and iOS IPA binaries, mapped to the OWASP Mobile Top 10 (2024)
ASMSubdomains, ports, services, TLS posture and breached credentials, with hourly or daily monitors
Container and IaCDocker/OCI image archives, CycloneDX/SPDX SBOMs and Kubernetes manifests; Terraform, CloudFormation and Helm listed on the integrations page
AI Pentester / Red TeamingAuthorization-gated PTES engagements and scoped autonomous testing on the DAST engine
GRC (early access)Risk register, audits and framework packs such as NCA ECC-2:2024, SAMA CSF and ISO/IEC 27001

Customer references are anonymized. The vendor lists sectors rather than names: healthcare, automotive, armed forces, banks, government, EU agencies and consulting firms.

What are Offensive360’s key features?

SAST with taint and data-flow analysis

The SAST engine models source code, follows untrusted input to sinks such as queries, file operations, templates and process calls, then applies security rules. Findings carry CWE and OWASP mapping plus remediation guidance.

The vendor quotes 60+ languages. The knowledge base is more specific and documents these source-language families:

Language familyTypical inputsFrameworks named by the vendor
C# / .NET.cs, .cshtml, .aspx.NET Framework, .NET Core
Java.java, JSPSpring, Struts, JEE
JavaScript / TypeScript.js, .jsx, .ts, .tsxNode.js, Express, React, Angular, Next.js, NestJS
Python.pyDjango, Flask, FastAPI
PHP.php, .phtml, .incLaravel, Symfony, WordPress
Go / Ruby.go, .rb, .ruGin, Echo, Rails, Sinatra
Kotlin / Swift / Objective-C / Dart.kt, .swift, .m, .dartAndroid, iOS, Flutter
C / C++.c, .cpp, .cc, headersSystems and embedded code
Apex.cls, .triggerSalesforce
Oracle Forms / PL/SQLReadable Forms exports, PL/SQL sourceOracle

The vendor’s docs add two caveats. Oracle Forms needs readable exports, since parsing binary .fmb or .pll files is not documented.

A Rust secure-coding guide exists, but Rust is not among the documented SAST language families.

Offensive360 SAST scan detail with scan status, lines of code, and tabs for vulnerabilities, dependencies, malware and license findings

Dependency, malware and license checks

A scan result splits into four tabs: Vulnerabilities, Dependencies, Malware and License. The GitHub Action exposes each extra analysis as a separate input, all off by default.

Dependency analysis reads supported manifests and lockfiles.

Offensive360 project overview showing total scans, vulnerability counts by severity, scan history and vulnerability resolution charts

Container and IaC checks

The container security product assesses uploaded Docker or OCI image archives, CycloneDX or SPDX SBOMs and Kubernetes manifests. It does not connect to live clusters or registries.

The integrations page also lists scanning for Dockerfiles, Helm charts, Terraform and CloudFormation. The vendor says availability and limits should be confirmed for each deployment.

DAST with headless crawling and 40+ active checks

The DAST engine renders JavaScript-heavy single-page apps in headless Chromium, discovers pages, forms and API calls, and then attacks each endpoint. Findings ship with the request and response that prove them.

Check classExamples from the vendor’s list
InjectionSQL (error, boolean, time-based), OS command, LDAP, XPath, NoSQL, expression language, SSTI, SSI
Cross-site scriptingReflected, stored, DOM-based, client-side template injection, blind XSS confirmed out-of-band
Authentication and sessionsSession fixation, JWT misconfiguration and replay, password-reset poisoning, default credentials
Access controlIDOR/BOLA, BFLA, mass assignment tested against an 18-field dictionary of privileged attributes
Server-side and parsingSSRF, XXE, insecure deserialization (Java, PHP, .NET, Python), path traversal, file upload
Protocol and infrastructureRequest smuggling, web cache poisoning, host-header, CRLF, prototype pollution, weak TLS
APIREST and GraphQL: introspection, BOLA, mass assignment, resource-consumption limits
AI and LLM appsOWASP Top 10 for LLM Applications (2025): prompt injection, system prompt leakage, output handling

Authenticated scanning supports form login, token and cookie sessions, multi-step flows and role-based testing.

Blind SSRF, XXE and XSS are confirmed through a self-hosted out-of-band callback service, so no third-party collaborator server is involved.

Safe mode is on by default and denial-of-service techniques are force-disabled in every mode. The vendor also says each engine release must produce zero findings against clean control applications before it ships.

Note
Same engine, three modes
The point-in-time DAST scan, the authorization-gated AI Pentester and Autonomous Red Teaming all run on one engine. ASM discovers external assets and hands them to any of the three for authorized testing.

Mobile and attack surface modules

MAST decompiles the APK, AAB or IPA you ship and checks secrets, storage, cryptography, network configuration and platform settings. Reports map to the OWASP Mobile Top 10 (2024) and export as PDF.

ASM starts from a seed scope of domains and emails. It enumerates subdomains, resolves hosts, checks ports, services and certificates, and correlates breached credentials, with change alerts on an hourly or daily cadence.

IDE plugins and the MCP server

IDE plugins cover VS Code, Visual Studio, IntelliJ, Android Studio and Eclipse. Each has its own repository under the Offensive360 GitHub organization.

The open-source MCP server gives Claude Code, Claude Desktop, Cursor and other MCP clients two tools.

o360_scan_path zips a local directory and returns findings with file, line, severity and fix. o360_scan_status reports queue position.

How does Offensive360 deploy on-premise and air-gapped?

Deployment is where Offensive360 differs most from SaaS-first scanners. SAST, DAST, MAST and ASM ship inside one virtual appliance, and targets, code and findings stay in your environment.

OptionDeliveryWhat to confirm
CloudHosted SaaS, same engineHosting location, data handling, retention, product availability
On-premiseOVA for your data center, or Azure VHD in your own tenantSizing, backup, upgrades, permitted network connections
Air-gappedSame appliance with no internet accessOffline licenses, rule and advisory updates, integration limits

The changelog dates the offline work. The August 31, 2026 release made all core language engines analyze fully offline, and Azure images carry a LUKS-encrypted payload with key release through a licensing relay.

Warning
Feature parity is not automatic
The vendor’s deployment page says not to assume identical capabilities across cloud, on-premise and air-gapped. External AI providers and connected integrations need separate setup, so run a disconnected acceptance test before signing.

What does Offensive360 integrate with?

The SAST product page lists GitHub Actions and a GitLab CI template as native options. Bitbucket, Azure DevOps, Jenkins and CircleCI connect through the REST API and a built-in setup wizard.

CI/CD and source control
GitHub Actions GitHub Actions
GitLab CI GitLab CI
Bitbucket Bitbucket
Azure DevOps Azure DevOps
Jenkins Jenkins
CircleCI CircleCI
Tickets, alerts and SIEM
Jira Jira
Slack Slack
Microsoft Teams Microsoft Teams
FortiSIEM (syslog) FortiSIEM (syslog)

Jira tickets are created automatically with severity mapping, and webhooks cover other systems. Syslog forwarding to a SIEM was validated end to end with FortiSIEM, per the August 20, 2026 changelog entry.

How does the free SAST GitHub Action work?

Public repositories on GitHub, GitLab, Bitbucket or Codeberg can request a free scan token. Tokens usually arrive within one business day, last 30 days, and renew by replying to the issuance email.

The offensive360/sast-scan-action repository is MIT-licensed and was released in August 2026. This is the quick-start workflow from its README:

name: SAST
on:
  push:
    branches: [main]
  pull_request:

permissions:
  contents: read
  security-events: write   # only needed when upload-sarif is enabled

jobs:
  sast:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: offensive360/sast-scan-action@v1
        with:
          api-url: https://sast.offensive360.com   # or your own on-prem instance
          api-token: ${{ secrets.O360_API_TOKEN }}
          upload-sarif: 'true'
          fail-on: high
InputDefaultPurpose
api-urlrequiredBase URL of the cloud or on-premise instance
api-tokenrequiredExternal scan token, stored as a repository secret
fail-onhighFails the job at or above none, low, medium, high or critical
upload-sariffalseSends results to the GitHub code scanning tab
dependency-scan / malware-scan / license-scanfalseAdds SCA, malware and license analysis
timeout-seconds3000Maximum wait for the scan

The action zips the workspace and uploads it to the instance in api-url.

Large repositories can hit the cloud proxy’s time limit. The README suggests scanning a subdirectory or using your own instance.

The free program is SAST only and runs on a shared cloud instance. Scanning private or commercial code with an open-source token gets the token revoked.

Offensive360 vs Checkmarx

Checkmarx One is the broader platform. It bundles SAST, SCA, DAST, IaC, container, API security, secrets detection and ASPM, supports 150+ languages and technologies, and offers SaaS and self-hosted deployment.

Offensive360’s published portfolio covers SAST, SCA, DAST, MAST, ASM, container artifacts, AI-driven pentesting and early-access GRC. ASPM is not on that list.

What sets it apart is one offline appliance with in-house engines, licensed without counting developers.

Checkmarx quotes vary with developer count and scanner selection, according to my Checkmarx review. Offensive360 sizes its license by products and scan scope instead.

Pick Checkmarx if you need ASPM, 150+ languages and a long enterprise record from one vendor. Pick Offensive360 if an air-gapped SAST plus DAST appliance and seat-free licensing matter more.

Offensive360 vs Fortify

Fortify Static Code Analyzer is OpenText’s long-running enterprise SAST. It detects 1,700+ vulnerability categories across 33+ languages and 350+ frameworks, with on-premises, SaaS and hybrid options.

Fortify covers legacy languages such as COBOL and ABAP and has a two-decade record in government and defense. Offensive360 does not list COBOL or ABAP among its documented language families.

Offensive360 packages SAST and DAST in one offline appliance, delivered as an OVA or Azure VHD image, and offers free SAST for open-source projects.

Pick Fortify if legacy-language coverage or an established OpenText relationship drives the decision. Pick Offensive360 if you want SAST and DAST together in one fully offline appliance.

Offensive360 vs SonarQube

SonarQube pairs code quality with security. The free Community Build is self-hosted, paid Server editions reach 35+ languages, and Developer Edition starts at a published $750 per year.

SonarQube’s strength is quality gates and breadth across bugs, code smells and security. Taint analysis sits in the Enterprise edition, and SonarQube has no DAST.

Offensive360’s code analysis is security-focused. It adds taint-based SAST, runtime DAST, mobile binary analysis and offline operation.

SonarQube has the more developed code-quality and quality-gate offering, and Offensive360 publishes no price.

Pick SonarQube for quality plus baseline security with a public price list. Pick Offensive360 when you need SAST and DAST together inside an isolated network.

How much does Offensive360 cost?

Offensive360 publishes no list prices. Both plans on its pricing page are a “custom annual license”, and the page states there is no per-seat fee.

Plan or programPublished priceWhat the vendor lists
Application Security (platform)Custom annual licenseSAST and DAST options, CI/CD integrations, team collaboration, scope agreed in proposal
On-Premise (enterprise)Custom annual licenseOVA appliance, air-gapped option, support terms and service levels in proposal
Open-source programFreeSAST only, public repositories, 30-day renewable tokens
EvaluationFree scans on requestPersonalized demo and evaluation scans

The About page describes an “unlimited scanning model” with no per-scan fees under one annual license. The Action README goes further and says “flat pricing, unlimited users and scans”.

The pricing page itself says scanning scope is agreed in the proposal. I would get the scope wording in writing before treating the license as unlimited.

How do you get started with Offensive360?

  1. Pick a path. Open-source maintainers request a free token on the free-for-open-source page. Commercial teams book the 30-minute demo or ask for evaluation scans.
  2. Choose a deployment. Use the cloud instance for a quick trial, or request the OVA or Azure VHD appliance if code cannot leave your network.
  3. Add a CI step. Drop in offensive360/sast-scan-action@v1 or the GitLab CI template, with the token stored as a secret and fail-on set to your gate.
  4. Review and retest. Check skipped files and analyzer status in the scan summary, triage findings with their evidence, fix, and rescan.

When should you use Offensive360?

I would shortlist Offensive360 for regulated teams that cannot send code or scan traffic outside their network. Government, defense, banking and healthcare buyers needing SAST and DAST offline are the clearest match.

It also fits organizations with many developers and few security staff. Developer count is not the pricing metric, although product mix and scanning scope can change the quote.

It is a weaker fit if you need a code-quality program, an ASPM layer, or COBOL and ABAP coverage. Teams that want named customer references will find only anonymized sector lists.

For a primer on combining static and runtime testing, see SAST vs DAST vs IAST .

What are alternatives to Offensive360?

  • Checkmarx One : enterprise platform with SAST, SCA, DAST, IaC, container, API and ASPM, in SaaS or self-hosted form.
  • Fortify Static Code Analyzer : OpenText SAST with 33+ languages, strong legacy coverage and on-premises deployment.
  • HCL AppScan : SAST, DAST, IAST and SCA suite offered in cloud, on-premises and desktop variants.
  • SonarQube : self-hosted code quality and security with a free Community Build.

For broader lists, see Checkmarx alternatives , Fortify alternatives , or every reviewed tool in the SAST tools hub.

What are Offensive360’s limitations?

The language count needs checking. The vendor quotes 60+ languages, while the knowledge base documents 15 families, so ask for the analyzer matrix for your release.

The public footprint is small. The GitHub repositories had no stars when I reviewed them, customer references are anonymized, and the open-source Action dates only from August 2026.

One CI example conflicts with the repository. The integrations page uses offensive360/sast-action@v1 with different inputs from the offensive360/sast-scan-action README, so follow the README.

Container and IaC scope needs confirming. Container checks assess uploaded artifacts rather than live clusters, and the vendor says availability depends on the deployment.

Pricing needs a sales conversation. No figures are published, and the “unlimited” wording on some pages sits next to “agreed scan scope” on the pricing page.

Tip
Best for
Regulated or isolated environments that want SAST, DAST and mobile analysis from one offline appliance, licensed without per-developer seats.
Note: Commercial platform from O360 B.V. (Amsterdam). Free SAST is limited to public open-source repositories on 30-day renewable tokens; everything else is quote-based.

Frequently Asked Questions

What is Offensive360?
Offensive360 is an application security platform from O360 B.V. in the Netherlands. It combines SAST, DAST, mobile binary analysis (MAST), attack surface management, container artifact checks and dependency, malware and license analysis in one console, with AI-driven pentesting and an early-access GRC module alongside. Its scanning engines are built in-house, and the whole stack ships as a virtual appliance that can run air-gapped.
Is Offensive360 free?
Only for public open-source projects. Repositories on GitHub, GitLab, Bitbucket or Codeberg can request a free SAST scan token, valid for 30 days and renewable by email. The free program covers SAST only; DAST, SCA, mobile and malware analysis need a commercial license.
Can Offensive360 run in an air-gapped environment?
Yes. SAST, DAST, MAST and ASM ship in one virtual appliance, delivered as an OVA or an Azure VHD image. The August 31, 2026 release made all core language engines analyze fully offline. Optional external AI providers and some integrations still need connectivity, so the vendor recommends a disconnected acceptance test.
What languages does Offensive360 SAST support?
The vendor quotes 60+ languages. Its knowledge base documents 15 source-language families: C#/.NET, Java, JavaScript, TypeScript, Python, PHP, Go, Ruby, Kotlin, Swift, Objective-C, Dart, C/C++, Apex and Oracle Forms/PL/SQL. Rules and framework handling depend on the installed release.
How does Offensive360 compare to Checkmarx?
Both bundle SAST, SCA and DAST in one commercial platform with SaaS and self-hosted options. Checkmarx One supports 150+ languages and technologies and adds an ASPM layer. Offensive360 ships its in-house engines as an air-gappable appliance and does not price per developer.
What does Offensive360 DAST test for?
The DAST engine runs 40+ active exploit checks and 19 passive analyzers. Coverage includes SQL, command, template and NoSQL injection, XSS, SSRF, XXE, deserialization, request smuggling, BOLA/BFLA, JWT flaws and GraphQL introspection. It also tests LLM features against the OWASP Top 10 for LLM Applications (2025).
How much does Offensive360 cost?
Offensive360 does not publish prices. It sells a custom annual license sized by products and scanning scope rather than developer seats. The GitHub Action README describes the model as flat pricing with unlimited users and scans; the pricing page says scope is agreed in each proposal.